Hype Proxies

Google Disrupts NetNut: What It Means If You Rely On Residential Proxies

If you run web scraping, ad verification, AI data collection, price monitoring, or any data pipeline on residential proxies, you have a single point of failure most buyers never check. The story behind the headline isn't really about NetNut. It's about where proxy IPs come from, and what happens to your operation when that source becomes a problem.

Gunnar

Last updated -

Why Hype Proxies

Featured image with a dark green background and title "Google Disrupt NetNut: What It Means If You Rely on Residential Proxies" in large white text on the left side and the HypeProxies logo in left upper corner. On the right, a 3D metallic silver element depicts the NetNut logo above cracked server racks struck by a lightning bolt, symbolizing disruption to residential proxy infrastructure. Additional network and globe elements reinforce the theme of internet routing, proxy networks, and changes affecting residential proxy providers. The overall design highlights Google's impact on NetNut and the broader residential proxy ecosystem.

TL;DR

  • On July 2, 2026, Google's Threat Intelligence Group, the FBI, and Lumen disrupted NetNut, a residential proxy network. Google says that it ran on at least 2 million consumer devices, and that the operation cut the usable pool "by millions."

  • Google's reason: in a single week of June 2026, it observed 316 distinct threat clusters, cybercriminal and espionage groups, using NetNut nodes to hide their origin. Google reports the devices were enrolled through app SDKs, often without clear consent.

  • This isn't about one vendor. A pool built from borrowed consumer devices can be degraded overnight, so where your IPs come from is a stability and liability question.

  • Already relying on NetNut? You'll need to move. The questions to ask any replacement are below, so you don't take on the same risk.

What did Google do to NetNut?

According to Google's Threat Intelligence Group, working with the FBI and Lumen, the operation degraded NetNut's network by cutting its pool of usable devices "by millions". Google's report describes a network built on at least 2 million consumer devices being used as proxy exit nodes. Security researchers track NetNut's network as "Popa".

Google's stated reason: those exit nodes were being used on a large scale for malicious activity. In a single week of June 2026, Google says it observed 316 distinct threat clusters, including both cybercriminal and espionage groups. They routed through suspected NetNut nodes to hide their origin and run password-spray and credential-stuffing attacks.

How the network acquired those devices is the part that still matters when you choose your next provider. Per Google's report, NetNut populated its pool by distributing proxy SDKs bundled into apps and pre-installed on consumer hardware like smart TVs and streaming boxes. The report says owners were enrolled through offers to "share your unused bandwidth", and researchers found the apps often lacked clear consent. If that's right, a large share of those residential IPs came from people who never knowingly agreed to have their home networks used as exit nodes.

Google's response had three parts: it disabled the Google accounts it says NetNut used for command-and-control, shared technical indicators with platform providers and law enforcement, and enabled Google Play Protect to warn users and disable apps that carry NetNut's SDKs.

Law enforcement went further. The FBI and IRS Criminal Investigation seized NetNut's domain, along with hundreds of related domains.

NetNut's parent company, the publicly traded Alarum Technologies (NASDAQ: ALAR), has disputed the "botnet" label for its software, while also saying it takes the matter seriously and will cooperate with law enforcement. For our part, we're reporting what Google published, not making a legal judgment of our own.

This is a pattern, not an exception

NetNut isn't an isolated case, and Google's own title says so: this is its continued disruption of residential proxy networks. In January 2026, Google disrupted IPIDEA, another of the largest residential networks, which quietly powered more than a dozen consumer-facing proxy brands. Days before NetNut, on June 28, 9proxy went offline and did not recover, with users reporting unresponsive support. We covered the IPIDEA takedown when it happened.

Google's reporting emphasises that this industry is interconnected. When one network gets degraded, operators buy capacity from competitors and resell it, which is how a single disrupted backend can be behind a dozen brand names you would never guess are related. So the name on your invoice is not the source of your IPs, and you can be paying one brand while routing through infrastructure that could fail without warning.

What does this mean for your operation?

Two things here still matter after the news fades.

Your supply is only as stable as its source. NetNut didn't lose a handful of IPs. Instead, it lost a large share of its exit nodes almost overnight because the network depended on consumer devices that a coordinated takedown could switch off. If your scraper, your monitoring, or your automation was routing through that pool, your success rate didn't degrade gracefully. It collapsed all at once. When the source of your IPs is a pool of borrowed consumer devices, your pipeline takes on every risk that pool carries: takedowns, sudden capacity loss, and a rush to replace it mid-project.

Sourcing is a liability question, not just a quality question. Most buyers evaluate proxies on speed, price, and success rate. NetNut is the reason to add a fourth: where the IPs come from. Pools built from consumer devices with unclear consent carry legal and reputational exposure that has nothing to do with what you're using them for. You can be doing legitimate work: price monitoring, market research, web scraping, ad verification and AI training data. The infrastructure underneath can still be one investigation away from disruption, or one headline away from becoming your compliance team's problem. When a provider gets taken down, its customers are not the target of the seizure, but they are the ones whose pipelines stop.

The question worth answering is simpler than any benchmark: where do these IPs come from, and can that source disappear?

How does HypeProxies source its proxies?

We source directly on infrastructure we own, not through a layer of borrowed consumer devices. That ownership is the reason a takedown like NetNut's does not reach our supply. Takedowns like this one target networks built on devices enrolled without clear consent and used on a large scale for crime. We're neither of those.

Our IPs don't come from app SDKs or bandwidth-sharing offers. Responsible providers now obtain proper consent for their app-based pools, which is an improvement over what Google described. But consented or not, it's still a pool of borrowed consumer devices, and that pool is exactly the layer that was degraded overnight.

Our IPs are 500K+ static US ISP addresses that sit on real carrier networks, which is why they read as ISP or residential in the IP reputation databases, not datacenter. Run one through any proxy checker, and you get a real ISP ASN, an "ISP" type, and a low fraud score. That is one of the first checks many sites run, the one that blocks datacenter ranges before they even evaluate your traffic.

Like every ISP proxy, ours runs on servers we own inside a datacenter, which is what makes it fast and stable. But that does not make it a datacenter proxy. What a site reads and blocks is the IP, not the datacenter the server runs in, and our IPs sit on real carrier networks, not the cloud and hosting ranges that read as datacenter. The server is in a datacenter. The IP is not.

Spur Intelligence, a firm that tracks proxy and anonymisation networks, found that 42% of the apps on LG's smart-TV platform carry SDKs that quietly turn the device into an exit node. After takedowns like these, any provider that claims ethical sourcing should be able to prove it. We're a proxy company writing about a competitor's takedown, so we mean that about ourselves too. Is there an SDK of ours in some app? Do we resell another network? Is there a get-paid-to app behind our service? For us, the answer to all three is no.

The three sourcing models compare as follows:


Datacenter

Residential (app/SDK)

Owned ISP (ours)

How the IPs are sourced

Spun up on cloud and hosting networks

Consumer home devices, enrolled through app SDKs

Static IPs on real carrier networks, on infrastructure we run

Consent

Not applicable

Often unclear or missing

No consumer devices in the path

How it reads in fraud databases

Datacenter, blocked by many sites immediately

Residential or ISP

Residential or ISP

What a coordinated takedown does

Nothing, but the trust was low to begin with

Can destroy most of the pool overnight, as NetNut demonstrated

No consumer-device layer to switch off

Datacenter and app-based residential are IPs rented from someone else's network, and you inherit its problems. Owned ISP is IP space on infrastructure we operate ourselves, so you inherit no one else's problems.

Clean sourcing won't control what a customer does with a proxy; nothing will. What it controls is which of three positions you're in when a takedown lands: the network that gets taken down, the reseller that goes down with it, or the standalone operation on its own supply that keeps running. It's what keeps you in the last of the three, and it's why our supply stays online.

Looking for a NetNut alternative? Here's what to check

NetNut's domain has been seized and its network degraded, so if you were routing through it, the question isn't whether to move but how quickly, and to which provider.

If you need stable supply right now, you can switch to cleanly sourced ISP proxies today, starting with a $1 trial. Because they use standard proxy protocols, switching is an endpoint change, not a rebuild. If you'd rather compare first, here's how we compare to NetNut and the other ISP providers.

If you're evaluating rather than switching under pressure, these three checks separate real ISP sourcing from marketing:

  1. Fraud score and IP type. Run the IPs through a checker. Real ISP IPs read as ISP or residential with a low fraud score; a "residential" pool that scores as datacenter is mislabeled.

  2. ASN and reverse DNS. A real carrier IP resolves to an ISP, not to a hosting company like AWS or OVH.

  3. The sourcing model. Ask where the IPs come from: owned infrastructure, a resold pool, or consumer devices enrolled through an app. Only the first is built to survive one.

Our free proxy checker runs the first two for you, no signup, and here's what's worth testing before you trust any ISP proxy. Speed and price are easy to compare. Sourcing is the part that decides whether your pipeline is still running next quarter, and it's the part we built so it doesn't fail when you check it.

Frequently asked questions

Why is NetNut not working?

Its domain was seized on July 2, 2026, and Google disrupted the network, cutting off much of the pool it ran on. If your NetNut proxies are down or have stopped working, that is why. Move to a provider on stable, owned infrastructure.

Is NetNut safe to use now?

No. As of July 2026, it's not safe to use. The FBI and IRS Criminal Investigation seized NetNut's domain on July 2, and Google degraded its network, so it isn't operating as a normal proxy service. The reason to leave isn't the downtime; it's where its IPs came from.

What is a good NetNut alternative?

A good NetNut alternative is one whose IPs come from owned infrastructure rather than a pool of consumer devices. Check how a provider sources its IPs before you commit. That matters more than speed or price.

What is the difference between ISP and residential proxies?

The difference is the source. Residential proxies route through consumer devices, usually enrolled through app SDKs. ISP proxies are static IPs on carrier networks, hosted on infrastructure the provider runs. Both read as residential; ISP is more stable because no consumer device can switch it off.

Can ISP proxies replace residential proxies?

For most use cases, yes, and with more stability. The exceptions are worth knowing: if your targets specifically need large, rotating pools of real residential or mobile IPs, or coverage outside the US, that is a different tool. Either way, the sourcing question still applies: ask where the IPs come from before you buy.

Why did Google disrupt NetNut?

Google says it disrupted NetNut because 316 distinct threat clusters used its exit nodes in a single week of June 2026, and because the devices were enrolled through app SDKs that often lacked clear consent.

Was NetNut a botnet?

Google and independent researchers describe NetNut as a botnet and track it as "Popa." Its parent, Alarum Technologies, disputes that label.

In this article:

Title

Share on

$1 one-time verification. Unlock your trial today.

In this article:

Title

Stay in the loop

Subscribe to our newsletter for the latest updates, product news, and more.

No spam. Unsubscribe at anytime.

Fast static residential IPs

ISP proxies pricing

Quarterly

10% Off

Monthly

Best value

Pro

Balanced option for daily proxy needs

$1.30

/ IP

$1.16

/ IP

$65

/month

$58

/month

Quarterly

Cancel at anytime

Business

Built for scale and growing demand

$1.25

/ IP

$1.12

/ IP

$125

/month

$112

/month

Quarterly

Cancel at anytime

Enterprise

High-volume power for heavy users

$1.18

/ IP

$1.06

/ IP

$300

/month

$270

/month

Quarterly

Cancel at anytime

Proxies

Bandwidth

Threads

Speed

Support

50 IPs

Unlimited

Unlimited

10GBPS

Standard

100 IPs

Unlimited

Unlimited

10GBPS

Priority

254 IPs

Subnet

/24 private subnet
on dedicated servers

Unlimited

Unlimited

10GBPS

Dedicated

Crypto

Quarterly

10% Off

Monthly

Pro

Balanced option for daily proxy needs

$1.30

/ IP

$1.16

/ IP

$65

/month

$58

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

50 IPs

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Standard

Popular

Business

Built for scale and growing demand

$1.25

/ IP

$1.12

/ IP

$125

/month

$112

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

100 IPs

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Priority

Enterprise

High-volume power for heavy users

$1.18

/ IP

$1.06

/ IP

$300

/month

$270

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

254 IPs

Subnet

/24 private subnet
on dedicated servers

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Dedicated

Crypto

Quarterly

10% Off

Monthly

Pro

Balanced option for daily proxy needs

$1.30

/ IP

$1.16

/ IP

$65

/month

$58

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

50 IPs

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Standard

Popular

Business

Built for scale and growing demand

$1.25

/ IP

$1.12

/ IP

$125

/month

$112

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

100 IPs

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Priority

Enterprise

High-volume power for heavy users

$1.18

/ IP

$1.06

/ IP

$300

/month

$270

/month

Quarterly

Cancel at anytime

Get discount below

Proxies

254 IPs

Subnet

/24 private subnet
on dedicated servers

Bandwidth

Unlimited

Threads

Unlimited

Speed

10GBPS

Support

Dedicated

Crypto